System and method for preventing access to data on a compromised remote device
Summary by NHIP
Remote Data Auto-Destruction System
The method transmits a compromise indication to a remote server and receives an instruction to auto-destroy data subsets while severing the connection. Triggers include theft prevention mechanisms, password failures, or missing communications at specified intervals, with options to copy data before destruction.
Claim Score by NHIP
Abstract
This invention discloses a system and method for selective erasure, encryption and or copying of data on a remote device if the remote device has been compromised or the level of authorization of a roaming user in charge of the remote device has been modified.

Term
Term ended
Expired 9 August 2023, 3.1 years ago.
- Priority and filed
- Granted
- Expired
- Today
17 claims: 3 independent, 14 dependent
- 1Broadest claimClaim Score 84, broad(NHIP)A method, comprising:transmitting, from a device and to a remote synchronization server, an indication that the device is compromised;and in response to transmitting the indication, receiving, at the device and from the remote synchronization server, an instruction that instructs the device to execute an auto-destruction of at least one subset of data available on the device, the instruction further instructing the device to sever a connection to the remote synchronization server.
- 7A device, comprising:a memory;and at least one hardware processor communicatively coupled with the memory and configured to: transmit, from the device and to a remote synchronization server, an indication that the device is compromised;and in response to transmitting the indication, receive, at the device and from the remote synchronization server, an instruction that instructs the device to execute an auto-destruction of at least one subset of data available on the device, the instruction further instructing the device to sever a connection to the remote synchronization server.
- 13A non-transitory computer-readable medium containing instructions which, when executed, cause a device to perform operations comprising:transmitting, from the device and to a remote synchronization server, an indication that the device is compromised;and in response to transmitting the indication, receiving, at the device and from the remote synchronization server, an instruction that instructs the device to execute an auto-destruction of at least one subset of data available on the device, the instruction further instructing the device to sever a connection to the remote synchronization server.
Independent claims3
119 paragraphs in 5 sections, as filed
CROSS REFERENCE TO RELATED APPLICATIONS
0001The present application is a continuation under 35 U.S.C. §120 of U.S. patent application Ser. No. 14/791,078, filed Jul. 2, 2015, which is a continuation application of U.S. patent application Ser. No. 14/192,802, filed Feb. 27, 2014 and now patented as U.S. Pat. No. 9,083,707, which is a continuation application of U.S. patent application Ser. No. 12/885,061, filed Sep. 17, 2010 and now patented as U.S. Pat. No. 8,696,765, which is a continuation application of U.S. patent application Ser. No. 10/637,267, filed Aug. 9, 2003 and now patented as U.S. Pat. No. 8,012,219, which claims benefit under 35 U.S.C. §119(e) to U.S. Provisional Patent Application No. 60/402,287, filed Aug. 9, 2002. Each of the above-referenced patent applications is hereby incorporated by reference in its entirety.
BACKGROUND OF THE INVENTION
0002This invention relates to the field of remote data access and, more particularly, to techniques for auto-destruction of data available on a remote device that has been compromised and is subject to be used by a user without authorization.
0003Data accessibility and consistency are frequently significant concerns for computer users. When a roaming user who has traveled to a remote location needs to review or manipulate data such as e-mails or documents, the roaming user must either carry the data to the remote location or access a workstation remotely. Because maintaining a true copy of a database containing the necessary data can be a cumbersome process, system designers have developed various techniques for connecting a remote device across a computer network to a server storing the data.
0004Millions of people, including employees of companies and organizations, use remote access technology for communication of data in the performance of their jobs. Companies and organizations are often under pressure for finding ways to rapidly and cost-effectively connect mobile employees to key organizational information utilizing existing and often disparate communications platforms and devices. Resolving the issues of access, synchronization, and security regarding remote access technology may be crucial to these organizations.
0005The use of remote access technology for communication of data may be one of the factors leading to the increasing importance of synchronization technology. When copies of the same data resides in more than one place, as the value of a copy of this data at one of these places is changed, the value of the copy of the same data at other locations must be updated to reflect the most recent change. Synchronization process refers to a process of updating data values to reflect the most recent changes' in the value. For example, a data value may be modified by the remote user by input of a new value to the remote device. By using the process of synchronization the value of copies of the same data at the server location is modified to reflect the change at the remote device. Data values may also be changed at the server location. In that case, the process of synchronization is needed to modify the values of the corresponding copies of data at the remote device in order to reflect the change at the server location. In short, the synchronization process may be used to update old values of data to become equal to the new values.
0006Synchronization of email over the Internet and generic synchronization of other workplace data such as files, contacts, and calendars is handled with appropriate applications. As users rely on multiple intelligent devices, that may be located at different places, to communicate and organize their key data, they need to synchronize the data collected at or communicated from different places to make sure that they have access to the most up to date version of data. Frequently, facilitating access and updating the remote user's data through synchronization allows the remote device to be in possession of the most up-to-date data available at the server housing the database. Synchronization also allows transmission of any changes to the data at the remote site back to the server. As such, the user in control of a remote device that is in communication with the central repository for the data at the server may cause modification of the data available on the server.
0007Because through synchronization changes to data by a remote user may cause changes to the data at the central repository, unauthorized change in the data at the remote location endangers the data at the central repository. In some example scenarios, the remote device may be lost or stolen or the user in control of the device may lose authorized status. In any scenario where the remote device falls in unauthorized hands, both the data on the remote device and the data at the server are in danger of being used without authorization, falsely modified, or deleted. Any of these events may at the least cause delay and loss of business and at the most prove catastrophic to the viability or the business of the organization. While transmissive encryption technologies may be used to ensure privacy of data in transit; transmissive encryption is usually irrelevant to the security measures that are needed in the case that the remote device itself is compromised or the remote user loses authorized status.
SUMMARY
0008Embodiments of the present invention provide a method, a system, and a computer program product for a user in charge of the data at an establishment, such as a company, a government agency, a private club, etc. to prevent misuse of data on a remote device that is in communication with a global server system at, for example, a central location of the establishment if the remote device has been compromised or the user of the remote device loses authorized status.
0009In an embodiment of the present invention, a method for erasing data from a compromised remote device is disclosed that comprises a) exchanging data with a remote device via a network, wherein the remote device has one or more types of data stored therein; b) receiving an indication that the remote device is compromised; c) selecting at least one of the one or more types of data for erasure in the remote device; and d) transmitting an order to erase data to the remote device via the network. In this embodiment, the order identifies the at least one type of data to be erased in the remote device and data of the type of data identified by the order is erased in the remote device upon receipt of the order by the remote device.
0010Other embodiments of this invention may include a system for auto-destruction of data on a remote device (remote device data) that is in communication with a server storing copies of the same data (server data) comprising a global server for storing and manipulating server data and remote device data and one or more one remote device for storing and manipulating remote device data. The global server and the remote devices are capable of communicating via a network. The server data includes non-synchronized and synchronized type data. The remote device data includes non-synchronized and synchronized type data as well. The global server includes a datastore for storing server data, a remote access server for communicating with the remote devices, and a synchronization server for communicating with the remote devices. The remote device server in turn has an autodestruct server for automatically destroying non-synchronized type remote device data and the synchronization server in turn has an autodestruct server for automatically destroying synchronized type remote device data. The remote devices include a datastore for storing remote device data, a remote access client for communicating with the remote access server, and a synchronization client for communicating with the synchronization server. The remote access client has an autodestruct client for automatically destroying non-synchronized type remote device data; and the synchronization client has an autodestruct client for automatically destroying synchronized type remote device data. The communication between the remote devices and the server comprises of communication between the remote access server and the remote access client, and communication between the synchronization server and the synchronization client. The remote devices may be capable of communicating among themselves as well.
0011In another embodiment of the invention, the autodestruct server may further comprise an erasure controller for controlling which remote device data is to be destroyed, a remote device connection severing requestor for requesting the remote device to sever its connection with the network, and a server connection severing engine for severing the connection between the global server and the network.
0012In another embodiment, the autodestruct client may further comprise a data tracker for keeping track of data transfers and remembering the final location where data is stored, a data eraser for erasing all or parts of remote device data, a reformatter for reformatting the remote device, and a remote device connection severing engine for severing the connection of the synchronization client or the remote access client with the network.
0013The embodiments of this invention include a method for auto-destruction of data by storing data in at least one category of data, in a server, each category of data stored in the server (server data) being either of a non-synchronized type or of a synchronized type, storing data in at least one category of data in a remote device, each category of data stored in the remote device (remote device data) being either of a non-synchronized type, of a synchronized type, or of a personally owned type, communicating the non-synchronized type data via a remote access connection between a remote access server of the server and a remote access client of the remote device, tracking the location, category, and type of each server data and each remote device data, executing a process of synchronization, being referred to as a synchronization event, receiving an indication marking at least one category of data, or alternatively at least one type of data, in the remote device for destruction or receiving an indication marking at least one type of data in the remote device for destruction, and requesting the remote device to activate a set procedure, to destroy the at least one category of data that is marked for destruction.
0014In one embodiment, the values of the server data and remote device data may include a time stamp indicating the time the value was last modified.
0015In another embodiment, the type of a category of data may be changed from the synchronized type to the non-synchronized type. Synchronized data categories whose type is changed to non-synchronized may include applications and timesheet data. The type of a category of data may also be changed from a non-synchronized type to the synchronized type. Examples of synchronized data categories whose type is changed to non-synchronized include applications and timesheet data.
0016The categories of data may include at least one of a category of e-mail data, a category of calendar data, a category of file data, a category of bookmark data, a category of task data, a category of sales force automation data, a category of customer relations management data, a category of corporate directory data, a category of personal information manager data, and a category of applications data.
0017The non-synchronized data categories include employee salaries and passwords, and the synchronized data categories include calendar data and corporate directory data.
0018In other embodiments, the change in the type of data may be communicated to the tracker by a user in charge of changing the type of data, where the change in the type of data is found out by the tracker during a subsequent synchronization event.
0019Synchronization may utilize the time stamps to determine the most recent data value corresponding to each data, where synchronizing the synchronized type data includes updating values of synchronized type data at one location if a corresponding value is modified at the other location, to reflect the most recent modification of the value of the data, on the synchronized type data via a synchronization connection between a synchronization server of the server and a synchronization client of the remote device. Synchronization may occur automatically, without initiation by a user. Synchronization may occur at predetermined times. Synchronization may occur periodically. It may occur upon detecting a change in a data value at the remote device, upon detecting a change in a data value at the server system, or upon instructions from a user.
0020In other embodiments, destruction may include complete erasure of the remote device data marked for destruction, tagging of the remote device data marked for destruction, or pointing to the remote device data marked for destruction.
0021In other embodiments, the set procedure may comprise destroying the synchronized type data on the remote device; requesting the remote device to reformat; requesting erasure of personally owned data on the remote device; requesting erasure of applications on the remote device; requesting erasure of non-synchronized data on the remote device; requesting erasure of synchronized data on the remote device; requesting encryption of all data, synchronized type data, personally owned data, non-synchronized data and/or applications on the remote device; severing the remote access connection between the remote device and the serve; severing the synchronization connection between the remote device and the server; and/or severing both the remote access connection and the synchronization connection between the remote device and the server.
0022In other embodiments, reformatting at the remote device may comprise requesting erasing all data from the remote device and severing the communication between the server and the remote device, and leaving the operating system of the remote device intact so that the remote device remains a thinking machine.
BRIEF DESCRIPTION OF THE DRAWINGS
0023The following figures depict examples of various systems and methods in accordance with embodiments of the present invention.
0024<figref idref="DRAWINGS">FIG. 1</figref> is a block diagram illustrating a network system.
0025<figref idref="DRAWINGS">FIG. 2</figref> is a block diagram illustrating an example of a computer system.
0026<figref idref="DRAWINGS">FIG. 3</figref> is a block diagram illustrating examples of categories of server data that may be stored as either synchronous or non-synchronous type data in the global server system.
0027<figref idref="DRAWINGS">FIG. 4</figref> is a block diagram illustrating types of server data.
0028<figref idref="DRAWINGS">FIG. 5</figref> is a block diagram illustrating types of remote device data.
0029<figref idref="DRAWINGS">FIG. 6A</figref> is a block diagram illustrating an autodestruct server system.
0030<figref idref="DRAWINGS">FIG. 6B</figref> is a block diagram illustrating an encryption server system.
0031<figref idref="DRAWINGS">FIG. 7A</figref> is a block diagram illustrating an autodestruct client system.
0032<figref idref="DRAWINGS">FIG. 7B</figref> is a black diagram illustrating an encryption client system.
0033<figref idref="DRAWINGS">FIG. 8A</figref> and <figref idref="DRAWINGS">FIG. 8B</figref> together depict a flowchart illustrating an example process for automatically destroying data and applications on a remote device and severing the connection of the remote device to the server system.
0034<figref idref="DRAWINGS">FIG. 9A</figref> and <figref idref="DRAWINGS">FIG. 9B</figref> depict flowcharts illustrating an example process for automatically destroying data and applications on a remote device and severing the connection of the remote device to the server system.
DETAILED DESCRIPTION OF CERTAIN INVENTIVE EMBODIMENTS
0035The statement of the problem in the Background section makes clear that a system and method are needed for preventing the unauthorized use of data on a remote device that is in communication with a central repository of data such as a server system. A system, method, and computer program product are presented here that address the problem of unauthorized access to data on a remote device or on a server that is in communication with the remote device.
0036<figref idref="DRAWINGS">FIG. 1</figref> is a block diagram illustrating a network system <b>100</b> in accordance with an embodiment of the present invention. As depicted in <figref idref="DRAWINGS">FIG. 1</figref>, the network system <b>100</b> includes a global server system <b>110</b> that is in communication with one or more remote devices <b>120</b> via a network <b>150</b>. The server system <b>110</b> may be coupled to the network <b>150</b> via any type of suitable connection such as wireless or wired (fiber-optics, coaxial cable, ISDN, copper wire, etc.) connections. Similarly, the remote devices <b>120</b> may be coupled to the network <b>150</b> via any suitable connection. Optionally, the remote device <b>120</b> and the server system <b>110</b> may be connected via direct wired or wireless connection. As such, the remote devices <b>120</b> may be mobile or stationary. Mobile devices are those that are portable and easily carried around by the user. Examples of mobile devices include mobile telephones, palm pilots, and laptop computers. The remote devices <b>120</b> may be in communication with other remote devices utilizing the network <b>150</b>.
0037It should be noted that the embodiments of this invention are capable of providing access to a broad assortment of remote devices that may be stationary or mobile computing devices and work with the most widely used enterprise messaging applications such as Microsoft Outlook and Lotus Notes. Examples of suitable networks <b>150</b> include WAN (Wide Area Networks), LAN (Local Area Networks), telephone networks, the Internet, or any other wired or wireless communication network.
0038The global server system <b>110</b> may include a server datastore <b>130</b>, a remote access server <b>116</b>, and a synchronization server <b>118</b>. The server datastore <b>130</b> may be used to store server data <b>115</b> that is synchronized with remote device data <b>121</b> or otherwise accessed by the remote device <b>120</b>. The remote access server <b>116</b> further includes an autodestruct server <b>117</b>, an encryption server <b>150</b>, and a set procedures file <b>170</b>. The synchronization server <b>118</b> further includes an autodestruct server <b>119</b>, an encryption server <b>152</b>, and a set procedures file <b>175</b>.
0039The remote device <b>120</b> may similarly include remote device datastore <b>135</b>, a remote access client <b>122</b>, and a synchronization client <b>124</b>. The remote device datastore <b>135</b> may be used to store remote device data <b>121</b>. The remote access client <b>122</b> further includes an autodestruct client <b>123</b> and an encryption client <b>160</b>. The synchronization client <b>124</b> further includes an autodestruct client <b>125</b> and an encryption client <b>162</b>.
0040The remote access server <b>116</b>, the synchronization server <b>118</b>, the remote access client <b>122</b>, the synchronization client <b>124</b>, and the security systems (not shown) of the server system <b>110</b> and those of the remote device <b>120</b> may support any suitable protocol that may for example include WAP (Wireless Application Protocol), WML (Wireless Markup Language), HDML (Handheld Device Markup Language), SMS (Short Message System), HTML (Hypertext Markup Language), HTTP (Hypertext Transfer Protocol), and/or SMTP (Simple Mail Transfer Protocol).
0041The remote access server <b>116</b> resides on the server system <b>110</b>, that may for example be located at a central location such as an organization's headquarter, and the remote access client <b>122</b> resides on the remote device <b>120</b>, for example at a roaming user's end. The remote access client <b>122</b> permits the remote device <b>120</b> to access the server data <b>115</b> via the remote access server <b>116</b>.
0042Copies of the same data <b>115</b>/<b>121</b>, or subsets thereof, may reside on the server <b>110</b> and the remote device <b>120</b> respectively. When copies of the same data reside in more than one place, as the value of this data at one of these places is changed, the value of the copy of the same data at other locations must be updated to reflect the most recent change. A synchronization process may be used to synchronize the data, i.e., to update old values of data to become equal to the new values.
0043The synchronization server <b>118</b> resides on the server system <b>110</b> while the synchronization client <b>124</b> resides on each remote device <b>120</b>. The synchronization server <b>118</b> and the synchronization client <b>124</b> operate to synchronize the copies (or subset(s)) of the data <b>115</b> on the server <b>110</b> with the copies (or subset(s)) of the same data <b>121</b> on the remote device <b>120</b>. A synchronization process may be executed automatically without any initiation from the user. For example, the synchronization server <b>118</b> and the synchronization client <b>124</b> may be set to execute the synchronization process at preset times, at preset intervals, or upon detecting a change in the data on one side. As another option, synchronization may be executed upon user instruction. Every time the synchronization process is executed, a synchronization event occurs. A synchronization event, thus, may occur at preset time intervals, every time data values at one end are changed, every time a user at one end wishes it, or according to some other criteria.
0044The synchronization server <b>118</b> and the synchronization client <b>124</b> operate to replace the older data values with the corresponding newer data values. Older data values may be distinguished from newer values using various methods such as time stamps. If, for example, each data value is further qualified with a time stamp, the synchronization server <b>118</b> and synchronization client <b>124</b> may use a comparison between the time stamps to identify the later data value and update the earlier data value to reflect the latest modifications to the value. Using the time stamp, the synchronization server <b>118</b> or client <b>124</b> selects the later data value that may replace the earlier version.
0045Illustrative examples of synchronization schemes that may be utilized for carrying out a synchronization process are disclosed in U.S. Pat. No. 6,023,708, titled “System and Method for Using a Global Translator to Synchronize Workspace Elements Across a Network,” by Mendez et al., U.S. Pat. No. 6,151,606, titled “System and Method for Using a Workspace Data Manager to Access, Manipulate and Synchronize Network Data,” by Mendez, and U.S. Pat. No. 6,085,192, titled “System and Method for Securely Synchronizing Multiple Copies of a Workspace Element in a Network,” by Mendez et al., all of which are incorporated by this reference.
0046The autodestruct server <b>117</b> of the remote access server <b>116</b> transmits erasure and other commands to the autodestruct client <b>123</b> of the remote access client <b>122</b> when a user of the remote device <b>120</b> loses authorization to use the device <b>120</b> or when the device <b>120</b> is compromised (e.g., lost, stolen). The commands can be included in a set procedures file <b>170</b> that indicates the procedures to follow. In an embodiment, the remote access client <b>122</b> erases a subset of data in the remote device data <b>121</b> that includes data remotely accessed from the remote access server <b>116</b> but is not necessarily synchronized with server data <b>115</b>. Alternatively, the subset of data can be thought of as one-way synchronized, i.e., changes in the corresponding subset of data in server data <b>115</b> leads to an update the subset in the remote device data <b>121</b>, but not vice versa. An example of this subset can include corporate directory data. The remote access client <b>122</b> can also erase personal data and applications in the remote device data <b>121</b>. Other commands in the set procedures file <b>170</b> can include formatting commands, communications link severance commands, encryption commands, copying, etc. In another embodiment of the invention, the autodestruct server <b>117</b> can instruct the autodestruct client <b>123</b> to first transmit specified data (e.g., non-synchronized and/or personal data) to the server datastore <b>130</b> for storage and then instruct the autodestruct client <b>123</b> to erase the data. The autodestruct server <b>117</b> and client <b>123</b> will be discussed in further detail below.
0047The encryption server <b>150</b>, in conjunction with the autodestruct server <b>117</b>, can transmit instructions in the set procedures file <b>170</b> to the encryption client <b>160</b>. Instructions for the encryption server <b>150</b> can include encrypting all or a subset of data from remote device data <b>121</b>, thereby preserving the data but preventing an unauthorized user from accessing the remote device data <b>121</b> on the remote device <b>120</b>. If the remote device <b>120</b> is recovered, the encrypted data can be decrypted and accessed. If the data is extremely sensitive and therefore the risk of misuse if decrypted very high, the autodestruct server <b>117</b> can instead instruct the autodestruct client <b>123</b> to erase the data instead of the encryption server <b>150</b> instructing the encryption client <b>160</b> to encrypt the data. In an alternative embodiment, the data can first be encrypted and then erased so that if the erased data is somehow recovered, it will still be in an encrypted format. The encryption server <b>150</b> and the client <b>160</b> will be discussed in further detail below.
0048The autodestruct server <b>119</b> and the encryption server <b>152</b> are substantially similar to the autodestruct server <b>117</b> and the encryption server <b>119</b> but generally operate to transmit instructions to the autodestruct client <b>125</b> and the encryption client <b>162</b>, which act upon synchronized data in the remote device data <b>121</b> in substantially similar fashion to the autodestruct client <b>123</b> and the encryption client <b>160</b>. The set procedures file <b>175</b> can be substantially similar to set procedures file <b>170</b> but may include different instructions because of the nature of the data acted on by the synchronization client <b>124</b>. It will be appreciated by one of ordinary skill in the art that the remote access server <b>116</b> and the synchronization server can be combined into a single unit that transmits instructions to the remote device <b>120</b> to operate on the remote device data <b>121</b>. The single unit can transmit instructions to the remote device <b>120</b> to operate on all remote device data <b>121</b> in a similar manner or to operate on the data <b>121</b> based on type (e.g., synchronized, non-synchronized, personal, etc.). Similarly, in an embodiment of the invention, the remote access client <b>122</b> and the synchronization client <b>124</b> can also be combined into a single unit to operate on the remote device data <b>121</b> based on data type. The remote device data and types will be discussed in further detail below in conjunction with <figref idref="DRAWINGS">FIG. 3</figref> and <figref idref="DRAWINGS">FIG. 5</figref>.
0049In an embodiment of the invention, the remote access client <b>122</b> and the synchronization client <b>124</b> of the remote device <b>120</b> can each include a set procedures file <b>180</b> and <b>185</b> respectively. The set procedures files <b>180</b> and <b>185</b> are substantially similar to the set procedures files <b>170</b> and <b>175</b> and are used when the remote device <b>120</b> self-initiates an autodestruct and/or encryption routine. The remote device <b>120</b> can self-initiate the procedures when it has determined that it has been compromised. For example, the remote device <b>120</b> can require the regular input of a code. If the scheduled input of the code is missed or if the inputted code is incorrect, this could indicate the device <b>120</b> has been compromised and therefore the remote device data <b>121</b> or a subset thereof needs to be encrypted or erased. This can be useful in situations when the remote device <b>120</b> has been compromised but is not in contact with the global server system <b>110</b> and so the system <b>110</b> cannot initiate procedures in the set procedures files <b>170</b> and/or <b>175</b>.
0050During operation of the network system <b>100</b>, the remote device <b>120</b> accesses data from the global server system <b>110</b>. For non-synchronized data, the remote access client <b>122</b> interacts with the remote access server <b>116</b>. For synchronized data, the synchronization client <b>124</b> interacts with the synchronization server <b>118</b> to exchange data according to synchronization processes known in the art. Synchronization between the server <b>118</b> and the client <b>124</b> can occur at regularly scheduled intervals or can be manually initiated by a user of the remote device <b>120</b> or the operator of the global server system <b>110</b>.
0051If the remote device <b>120</b> has been compromised (e.g., lost, stolen, or the user is no longer authorized to access data), the remote access server <b>116</b> and the synchronization server <b>118</b> can transmit instructions to the remote access client <b>122</b> and the synchronization client <b>124</b> respectively of the remote device <b>120</b> to encrypt and/or erase all or subsets of the remote device data <b>121</b>. In addition, the remote access server <b>116</b> and the synchronization server <b>118</b> can transmit instructions to the remote access client <b>122</b> and the synchronization client <b>124</b> respectively to transmit a copy of all or subset of the remote device data <b>121</b> to the global server system <b>110</b> or other location for storage and evaluation. In addition, as described above, if the remote device <b>120</b> is compromised, the remote device <b>120</b> can self-initiate an erasure and/or encryption routine.
0052<figref idref="DRAWINGS">FIG. 2</figref> is a block diagram illustrating an exemplary computer system <b>200</b> that may be utilized to carry out embodiments of the present invention. The server system <b>110</b>, the remote device <b>120</b>, and components of these systems may include such a computer system <b>200</b> or parts thereof. The computer system <b>200</b> includes one or more processors <b>202</b>, input devices <b>203</b>, output devices <b>204</b>, readers <b>205</b> for reading computer readable storage media, computer readable storage media <b>206</b>, a communication interface <b>207</b>, storage media <b>208</b>, and a working memory <b>209</b> that further includes an operating system <b>291</b> and other programs <b>292</b>. A bus <b>201</b> couples these components together.
0053The processor(s) <b>202</b> usually controls all the other parts and may generally include a control unit, an arithmetic and logic unit, and memory (registers, cache, RAM and ROM) as well as various temporary buffers and other logic. The control unit fetches instructions from memory and decodes them to produce signals that control the other parts of the computer system. Some illustrative examples of the processor(s) <b>202</b> may include Intel's PENTIUM and CELERON processors, Motorola's 14500B, or the like.
0054Input devices <b>203</b> or peripherals may be used to transfer data to and from the computer system. Some input devices may be operated directly by the user, such as keyboard, mouse, touch screen, joystick, digitizing tablet, or microphone. Other input devices may include sensors or transducers that convert external signals into data, for example, an analog to digital converter such as a microphone.
0055Output devices <b>204</b> may include electronic or electromechanical equipment coupled to the computer system and may be used to transmit data from the computer in the form of text, images, sounds or other media to the communication interface <b>207</b> that may be a display screen, printer, loudspeaker or storage device <b>208</b>. Most modem storage devices such as disk drives and magnetic tape drives act as both input and output devices, others are input only.
0056The communications interface <b>207</b> may be used to couple the bus <b>201</b> to a computer network <b>150</b> and may include an Ethernet card, a modem, or other similar software or hardware. Ethernet is a type of local area network, which sends its communications through radio frequency signals carried by a coaxial cable. Each computer checks to see if another computer is transmitting and waits its turn to transmit. Software protocols used by Ethernet systems vary, but include Novell Netware and TCP/IP. A modem connects computers to each other for sending communications via the telephone lines. The modem modulates the digital data of computers into analog signals to send over the telephone lines, then demodulates back into digital signals to be read by the computer on the other end.
0057Computer-readable storage medium readers <b>205</b> may be used to access and store information on the computer-readable storage media <b>206</b>. Computer-readable storage medium readers <b>205</b> may include disk drives, CD-ROM drives, or DVD drives. Computer-readable storage media <b>206</b> may include diskettes, CD-ROMs, or DVDs.
0058Storage <b>208</b> or memory is a device into which data can be entered, in which they can be held, and from which they can be retrieved at a later time. Storage <b>208</b> may include the hard disk space of the computer system <b>200</b> capable of permanently storing data and applications.
0059Working memory <b>209</b> may include random access memory (RAM) which, in turn, houses the operating system <b>291</b> and other programs <b>292</b>. The RAM may be built from semiconductor integrated circuits, which can be either static (SRAM) or dynamic (DRAM). RAM is usually volatile although non-volatile random-access memory may also be used.
0060The operating system <b>291</b> is a low-level software which handles various tasks for example interfacing to peripheral hardware, scheduling of tasks, allocating storage, and presenting a default interface to the user usually when no application program is running Some examples of the operating system <b>291</b> may include UNIX, XENIX, Linux, OS2/WARP, DOS, Windows, Windows 95, Windows 98, Windows CE, Windows NT, Windows 2000, Macintosh System 7, IBM's VM and VSNME or operating systems specifically engineered for handheld devices such as PalmOS, EPOC, Windows CE, FLEXOS, OS/9, and JavaOS, or any other type of operating system capable of operating various types of computers.
0061<figref idref="DRAWINGS">FIG. 3</figref> is a block diagram illustrating examples of various categories of server data <b>115</b>. The server data <b>115</b> and the remote device data <b>121</b> are stored in the server datastore <b>130</b> and the remote device datastore <b>135</b> respectively, may include one or more data categories. These categories may for example include email data <b>310</b>, calendar data <b>320</b>, file data <b>330</b>, bookmark data <b>340</b>, task data <b>350</b>, sales force automation data <b>360</b>, customer relations management data <b>370</b>, organizational directory data <b>380</b>, personal information manager (PIM) data <b>390</b>, various applications <b>395</b>, and other data types.
0062Examples of email data <b>310</b> may include the contents of an email, the dates it was sent and received, the addresses of the sender and the receiver, and the title of the email. Examples of calendar data <b>320</b> may include the dates and the events scheduled for each date and other characteristics of each date such as whether the date is a holiday or not. Examples of file data <b>330</b> may include file names, contents, dates of creation of the file, and file location. Examples of bookmark data <b>340</b> may include Internet addresses of bookmarked locations and an identifier or name corresponding to the address. Examples of task data <b>350</b> may include information about the tasks to be performed and the dates of performance and the personnel assigned for performance of each task. Examples of sales force automation data <b>360</b> may include data on automation of the sales activities of the salespersons of an organization. Examples of customer relations management data <b>370</b> may include various types of data about various customers of an organization. Examples of corporate (or other organization-type) directory data <b>380</b> may include: names, positions, locations, and contact information of the persons working for an organization. Examples of personal information manager (PIM) data <b>390</b> may include: data used by a person in the day-to-day management of the person's life and activities. Examples of various applications <b>395</b> may include: word processing applications such as Microsoft Word or WordPerfect, spreadsheet applications such as Lotus 1-2-3 and Excel, drafting applications such as AutoCAD, and the like. The server data <b>115</b> and remote device data <b>121</b> may include entire data files, applications, or other data units.
0063<figref idref="DRAWINGS">FIG. 4</figref> is a block diagram showing the server data <b>115</b> of the global server system <b>110</b>. The server data <b>115</b> may include two types of data, non-synchronized type data <b>410</b> and synchronized type data <b>420</b>.
0064Non-synchronized server data <b>410</b> may be defined as a type of data that should not be modified based on the modifications of data on a remote device <b>120</b>. Non-synchronized data <b>410</b> is served by the remote access server <b>116</b> to the remote access client <b>122</b>. This data may be either data that is not accessible (or even visible) to the remote device <b>120</b> or data that can be accessed and stored by the remote device <b>120</b> but should not be changed or altered by the remote device <b>120</b>. The synchronization process does not impact this type of data and does not update the data values of this type at the server location when the corresponding data value has been changed at the remote device location. Examples of non-synchronized data <b>410</b> may include sensitive data, for example, data relating to security such as passwords and encryption information, or employee salaries.
0065Synchronized data <b>420</b> may be defined as a type of data that can be synchronized utilizing a synchronization process. The synchronization server <b>118</b> can serve this data to the synchronization client <b>124</b>. As explained above, it is generally desirable to protect some data values from being changed by a user in the field; these are data that should either stay constant or be changed only at a central location by someone with central authority. On the other hand, synchronized data is the type of data that is permitted to be modified by a roaming user at the remote device <b>120</b> and the change in the data value is meant to be transferred to the corresponding server data <b>115</b> during a subsequent synchronization event. Examples of synchronized data may include the kind of data regularly collected by roaming users that utilize a remote device. This data may vary depending on the type of organization and may include sales data, technical data, scheduling data, census data, and the like. In these cases, the roaming user is usually in the best position to update the data value and it is desirable to communicate the update to the central location.
0066<figref idref="DRAWINGS">FIG. 5</figref> is a block diagram showing types of remote device data <b>121</b>. The remote device data <b>121</b> include non-synchronized remote device data <b>510</b>, synchronized remote device data <b>520</b>, and personally owned remote device data <b>530</b>.
0067As explained in the context of server data types, if and while the data values on the remote device are classified as non-synchronized data type <b>510</b>, these data will not be affected by changes in the corresponding data values on the server system <b>110</b>. Conversely, a change in the data value on the remote device <b>120</b> will not automatically impact the value of the corresponding data on the server system <b>110</b>. However, in an alternative embodiment, the non-synchronized data type <b>510</b> can actually be one-way synchronized. That is, changes in server data <b>115</b> will change the remote device data <b>121</b>, but not vice versa. The non-synchronized server data <b>410</b> may be accessed by the remote device <b>120</b> through the use of the remote access client <b>122</b> and the remote access server <b>116</b>. The non-synchronized remote device data <b>510</b> may include the same categories of non-synchronized server data <b>410</b> and may further include categories of data different from non-synchronized server data <b>410</b>. Typically, the non-synchronized remote device data <b>510</b> may belong to the entity controlling the server system. Examples of non-synchronized remote device data <b>510</b> may include sensitive data, for example, data relating to security such as passwords and encryption information, or employee salaries.
0068The synchronized remote device data values <b>520</b> may be updated during a synchronization event if the corresponding synchronized server data <b>420</b> values have been modified since the last synchronization event. At the same time, any modifications in the synchronized remote device data <b>520</b> will result in corresponding changes in the synchronized server data <b>420</b> during a subsequent synchronization event. Those data categories that may be freely modified by the user of the remote device <b>120</b> usually fall under the synchronized type. Also, when it is crucial that the roaming user has access to the most current value of a data category, this category must be classified as synchronized data <b>520</b> and must be updated regularly with changes on the server system side <b>110</b>. Calendar data and organizational directory data are examples of categories of data that fall under this type.
0069The personally owned data <b>530</b>, in contrast to the previous types, belongs to the user of the remote device and ideally speaking should not be accessed or modified by the user in charge of handling the data and the server system, for example an information technology administrator at a company. In an example scenario, the remote device <b>120</b> in custody of the roaming user belongs to the organization in control of the server system <b>110</b> and is controlled by the user in charge of controlling the server system. The organization may authorize the roaming users to install personal data or applications on the remote devices assigned to them. In such cases, the user in charge of controlling the server system may wish to steer clear of the personally owned data <b>530</b> stored on a remote device. This data, therefore, is assigned its own type.
0070Each category of data may be assigned a synchronized or non-synchronized type. The various categories of data <b>310</b>, <b>320</b>, <b>330</b>, <b>340</b>, <b>350</b>, <b>360</b>, <b>370</b>, <b>380</b>, <b>390</b>, <b>395</b>, etc. may be assigned the synchronized type <b>410</b> or the non-synchronized type <b>420</b> by the user in charge of the data. Generally speaking, calendar data <b>320</b>, some file data <b>330</b>, bookmark data <b>340</b>, sales force automation data <b>360</b>, and customer relations management data <b>370</b> are categories of data that need to be accessed and modified by the users carrying the remote device <b>120</b> in order to be up to date. These categories of data may be set to the synchronized type <b>420</b> by the user in charge of the data. As such, a change in the data <b>121</b> in one of these categories on the remote device <b>120</b>, effected by the roaming user that may be, for example, a field employee, will be reflected at the server system <b>110</b> by a corresponding change in the synchronized data <b>420</b> on the server system <b>110</b>. On the other hand, ordinary applications <b>395</b> are generally, but not always, non-synchronized <b>510</b>.
0071The user in charge of handling the data may move categories of data in and out of the non-synchronized type <b>410</b> on the server system <b>110</b>. In other words, the type of each data category on the server system <b>110</b> may be changed depending on the circumstances. As a result, the corresponding categories of data on the remote device <b>120</b> may move in and out of the non-synchronized type <b>510</b> as well.
0072An example of moving a category of data in and out of the non-synchronized type <b>510</b> is keeping client information data that are being entered into the remote device <b>120</b> by a roaming user in the field in the non-synchronized type <b>510</b> until the user in charge of handling the data at the server location verifies them. In this manner, the client information data, being entered by the roaming user, may not affect the corresponding data at the server location. As long as the data being entered in the field is set as non-synchronized type, the changes in data value will not be transferred to the server location during a synchronization event. After the user in charge of handling the data at the server location decides that the field entries are credible, the corresponding server data <b>115</b> may be safely updated by the field entries. Only then, this category of data may be moved from the non-synchronized type <b>510</b> to the synchronized type <b>520</b>. And only then, the server data <b>420</b> will be synchronized with the newly modified remote device data <b>520</b>.
0073Another example of a category of data that may be moved in and out of the non-synchronized type <b>510</b> may include applications such as word processing programs or spreadsheet programs. For example, every time a new version of an application is installed on the server system <b>110</b>, the user in charge of the data at the server may change the type of the application category to synchronized <b>420</b> so that the remote devices <b>120</b> may also update their versions of the application through synchronization. After all the remote devices have synchronized their corresponding applications, it is generally more desirable to keep the applications in the non-synchronized type <b>510</b> so that a version of the application installed by a user of the remote device is not permitted to corrupt the central copy at the server location.
0074Another example of a category of data that may need to be changed from synchronized type to non-synchronized type and back again are timesheet entries of employees of an entity. Timesheet entries of each employee may be synchronized throughout a month but at the end of each month an IT administrator may move timesheet entries into the non-synchronized data type and prevent the employee-users to further modify their entries.
0075Moving the categories of data between the synchronized <b>420</b> and the non-synchronized type <b>410</b> may be advantageous in many situations. For example, a variety of security risk scenarios can be handled by embodiments of this invention. For example, if erasure happens accidentally at the remote device <b>120</b>, no permanent loss occurs as long as the deletion is not transferred back to the server system during a synchronization event. To prevent accidental or malicious erasure of data at the server system <b>110</b>, sensitive categories of data, that are usually not to be modified by users of the remote devices <b>120</b>, may be set to the non-synchronized type <b>410</b>. If this data need to be updated on occasion, the user in charge of handling the data may change the data type to synchronized <b>420</b> during an active supervision period when he can ensure that the server data <b>115</b> are modified according to credible modifications in the remote device data <b>121</b>. Subsequently, the user in charge of handling the data may change the data type back to non-synchronized <b>410</b> and protect it from modification by the remote device.
0076<figref idref="DRAWINGS">FIG. 6A</figref> is a block diagram illustrating an autodestruct server system <b>600</b>. This block diagram may refer to the autodestruct server <b>117</b> included in the remote access server <b>116</b> or the autodestruct server <b>119</b> included in the synchronization server <b>118</b>. Both autodestruct server systems <b>117</b> and <b>119</b> have similar components that perform generally the same operations. Therefore, the components of the two autodestruct server systems <b>117</b> and <b>119</b> are being discussed together. The differences are being discussed after the common points are set forth.
0077The autodestruct server system <b>117</b>, <b>119</b> is used to instruct the remote device <b>120</b> to destroy the remote device data <b>121</b>. The autodestruct server system <b>117</b>, <b>119</b> includes an erasure controller <b>610</b>, a remote device connection severing requestor <b>620</b>, and a server connection severing engine <b>630</b>.
0078The erasure controller <b>610</b> transmits a set of erasure instructions to the remote device <b>120</b> and controls which data from the remote device data <b>121</b> will be deleted according to instructions in the set procedures file <b>170</b> or <b>175</b>. The erasure controller <b>610</b> may be an application layer on the remote device <b>120</b> using an appropriate operating system depending on the remote device operating system (platform) that may vary between Windows, Palm, Epoch, and the like. The erasure command may be platform specific and erasure of data may be a complete erasure rather than tagging or pointing to the data that merely marks the data for deletion.
0079The remote device connection severing requestor <b>620</b> requests the remote device <b>120</b> to sever its connection with the network <b>150</b> that is connected with the server system <b>110</b>. In response to a request by this requestor <b>620</b>, the remote device <b>120</b> severs its connection with the network <b>150</b> and thus with other remote devices and the server system <b>110</b>. Once this connection is severed, the server system <b>120</b> and the erasure controller <b>610</b> of the autodestruct server <b>117</b> or <b>119</b> have no access to the remote device <b>120</b> and may not control further erasure of data. However, because only those remote device or remote devices that are at issue are severed, the server system <b>110</b> still may access other remote devices whose connections to the network <b>150</b> remain intact.
0080The server connection severing engine <b>630</b> disconnects the connection between the server system <b>110</b> and the network <b>150</b> and thus disconnects the server system <b>110</b> from all remote devices in the field. This engine <b>630</b> may be used when all remote devices are compromised and the server system <b>110</b> needs to sever the connection with all devices <b>120</b>. Another example scenario of the use of this engine <b>630</b> is when an error is detected in the server system <b>110</b>, such as a virus attack. Preventing the propagation of the error or the virus requires the server system <b>110</b> to be isolated from connected devices such as all of the remote devices <b>120</b>. In short, this engine <b>630</b> is usually used when the server system <b>110</b> is compromised or when all the remote devices <b>120</b> are compromised as opposed to the time when a single remote device <b>120</b> or a subset of all of the remote devices <b>120</b> are compromised.
0081In another embodiment of the invention, the server connection severing engine <b>630</b> prevents the remote device <b>120</b> from accessing the server system <b>110</b> by deleting all authorization codes and/or related data (e.g., User ID, MAC ID, password, etc.) for the specific unauthorized remote device <b>120</b>.
0082The difference between the two autodestruct servers is that the erasure controller <b>610</b> of the autodestruct server <b>117</b>, residing within the remote access server <b>116</b>, applies to server non-synchronized data <b>310</b> whereas the erasure controller <b>610</b> of the autodestruct server <b>119</b>, residing within the synchronization server <b>118</b>, applies to server synchronized data <b>320</b>. However, it will be appreciated by one of ordinary skill in the art that the autodestruct servers <b>117</b> and <b>119</b> can be combined into a single unit.
0083<figref idref="DRAWINGS">FIG. 6B</figref> is a block diagram illustrating an encryption server system <b>650</b>. This block diagram may refer to the encryption server <b>150</b> in the remote access server <b>116</b> or the encryption server <b>152</b> in the synchronization server <b>118</b>. The encryption server <b>150</b> is substantially similar to the encryption server <b>152</b> by generally having the same components that operate in a similar fashion. The encryption server system <b>650</b> includes an encryption controller <b>660</b>, encryption algorithms <b>670</b>, and encryption keys <b>680</b>.
0084The encryption controller <b>660</b> sends instructions to the encryption client <b>160</b> and/or <b>162</b> in the remote device <b>120</b> to encrypt the remote device data <b>121</b> or a subset thereof. The encryption controller <b>660</b> can be initiated by a system <b>110</b> operator and can follow procedures listed in the set procedures file <b>170</b> and/or <b>175</b>. The set procedures for use by the encryption controller <b>660</b> can include sending a command to the remote device <b>120</b> to encrypt all or a subset of the remote device data <b>120</b>. The set procedures can also specify what type of encryption algorithm to use as listed in the encryption algorithms <b>670</b>. The keys used to encrypt and/or decrypt the data are stored in the encryption keys <b>680</b>.
0085<figref idref="DRAWINGS">FIG. 7A</figref> is a block diagram illustrating an autodestruct client system <b>700</b>. This block diagram may refer to the autodestruct client <b>123</b> included in the remote access client <b>122</b> or the autodestruct client <b>125</b> included in the synchronization client <b>124</b>. Both autodestruct client systems <b>123</b> and <b>125</b> have the same components that perform generally the same operations. Therefore, the components of the two autodestruct client systems <b>123</b> and <b>125</b> are being discussed together. The differences between the two are being discussed after the common points are set forth.
0086The autodestruct client system <b>700</b> is used to erase the remote device data <b>121</b> or a subset thereof. The autodestruct client <b>700</b> includes a data tracker <b>710</b>, a data eraser <b>720</b>, a reformatter <b>730</b>, and a remote device connection severing engine <b>740</b>.
0087The data tracker <b>710</b> system keeps track of the transfers of data and remembers the final location where the data is stored in the storage <b>208</b>, the working memory <b>209</b>, the computer-readable storage medium <b>206</b>, or elsewhere. Data is communicated between the remote devices <b>120</b> and the server system <b>110</b>, or between the remote devices <b>120</b> that are permitted to communicate with one another. The communicated data falls within various types and categories. Every data communicated may be assigned the non-synchronized <b>410</b>, <b>510</b>, or synchronized <b>420</b>, <b>520</b> type. Personally owned data <b>530</b> is generally not communicated between devices. Data falling within this data type may however be tracked and distinguished from other types as well. Every data from a category such as email data <b>310</b>, calendar data <b>320</b> or the like may further fall within a particular type of non-synchronized <b>410</b>, <b>510</b>, synchronized <b>420</b>, <b>520</b> or personally owned <b>530</b>. Data to be synchronized <b>410</b> may first be identified and marked as such by the user in charge of the data. When a synchronized type data <b>410</b> is communicated, to a remote device <b>120</b>, the data tracker <b>710</b> keeps track of the location and type of this data. If the user in charge of the data later changes the type assigned to this data, during the next synchronization event the data tracker <b>710</b> finds out that the data is no longer of the synchronized type <b>410</b> and changes the type assigned to that data. In another option, the change in the type of a data may be communicated by the server system to the data tracker <b>710</b> as the change takes place. As such, when an erasure command is received for the synchronized data only, the data tracker <b>710</b> knows which data are assigned the synchronized type and need to be erased and which are not. The data tracker <b>710</b>, further has record of the location of the data to be erased within the storage <b>208</b>, the working memory <b>209</b>, on a computer-readable storage medium <b>206</b>, or any other physical location on the computer system <b>200</b> that the data may be.
0088The function of the data tracker <b>710</b> may be likened to that of a list. In effect, the data tracker <b>710</b> provides the remote device <b>120</b> with lists of the various types of data and maintains these lists dynamically as the type of a certain data unit is changed or as the storage location of the data unit is changed. Depending on how often synchronization is set to occur: every time a synchronization order is dispatched by the server system <b>110</b>, at synchronization intervals preset by a user in charge of the data or the user of the remote device, every time a data unit is updated at the remote device <b>120</b> end, and/or according to some other rule, the data tracker <b>710</b> identifies the synchronized remote device data <b>520</b> that must be synchronized with the synchronized server data <b>420</b>.
0089The data eraser <b>720</b> system is capable of erasing all or parts of the remote device data <b>121</b> on demand from the system <b>110</b> or based on a self-initiation following set procedures <b>180</b> and/or <b>185</b>. The data eraser <b>720</b> controls which data will be deleted from the remote device data <b>121</b> as indicated by the data tracker <b>710</b>. For example, the data eraser may erase only synchronized data <b>520</b> or only personal data <b>530</b>. The data eraser may use an appropriate operating system depending on the remote device operating system (platform) that may vary between windows, Palm, Epoch, and the like. The erasure command may be platform specific and erasure of data may be complete erasure rather than mere tagging or pointing to the data that is marked for deletion.
0090The reformatter <b>730</b> reformats the remote device <b>120</b> storage area <b>208</b>. By doing so, the reformatter <b>730</b> erases all data and severs the connection between the remote device <b>120</b> and the network <b>150</b>. The reformatter <b>730</b> does not distinguish between data types or categories. The operation of the reformatter <b>730</b> erases the personally owned data <b>530</b> of the remote device <b>120</b> as well. In an embodiment of the invention, the reformatter <b>730</b> does not erase the operating system <b>291</b> of the remote device <b>120</b> and thus leaves the remote device <b>120</b> a thinking and operating machine without its original data or applications <b>121</b>.
0091The remote device connection severing engine <b>740</b> severs the connection of the synchronization client <b>124</b> or the remote access client <b>122</b> with the network <b>150</b>. As a result of operation of this engine <b>740</b>, the remote device <b>120</b> may no longer communicate the particular type of data with the server system <b>110</b> or other remote devices <b>120</b>. The connection severing engine <b>740</b> leaves the remote device data <b>121</b> intact if initiated before the data eraser <b>720</b> or the reformatter <b>730</b> is instructed to operate. If the connection severing engine <b>740</b> of the autodestruct client <b>123</b> of the remote access client <b>122</b> operates, the communication of non-synchronized data <b>510</b> will be terminated. If the connection severing engine <b>740</b> of the autodestruct client <b>125</b> of the synchronization client <b>124</b> operates, the communication of synchronized data <b>520</b> will be terminated. In a possible scenario, the connection severing engine <b>740</b> of the autodestruct client <b>123</b> of the remote access client <b>122</b> may sever the communication of the non-synchronized data <b>510</b>. If the data type is subsequently modified by the user in charge of the data from non-synchronized <b>410</b> to synchronized <b>420</b>, that same data will be communicated to the synchronization client <b>124</b>. As such, the operation of the connection severing engine <b>740</b> is selective with respect to the type of data it isolates from communication.
0092One difference between the autodestruct client <b>123</b> included within the remote access client <b>122</b> and the autodestruct client <b>125</b> included within the synchronization client <b>124</b>, is that the data eraser <b>720</b> of the autodestruct client <b>123</b> included in the remote access client <b>122</b>, applies to client non-synchronized data <b>510</b> and personally owned remote device data <b>530</b> whereas the data eraser <b>720</b> of the autodestruct client <b>125</b>, included in the synchronization client <b>124</b>, applies to client synchronized data <b>520</b>.
0093Another difference between the autodestruct client <b>123</b> of the remote access client <b>121</b> and the autodestruct client <b>125</b> of the synchronization client <b>124</b> is that data tracker <b>710</b> of autodestruct client <b>123</b>, residing within the remote access client <b>122</b>, tracks the client non-synchronized data <b>510</b> and the tracker <b>710</b> of the autodestruct client <b>125</b>, residing within the synchronization client <b>124</b>, tracks the client synchronized data <b>520</b>. Each data tracker <b>710</b> keeps track of data that is communicated to the remote device <b>120</b> or entered into the remote device through its input device <b>203</b> by the user. If a data unit (point, file, application, etc.) is moved by the user in charge of the data from the synchronized type <b>420</b> to the non-synchronized type <b>410</b>, the tracker <b>710</b> recognizes the change once that data is communicated to the remote device <b>120</b>. In one scenario, a synchronized data <b>420</b> is communicated to the remote device <b>120</b> by the synchronization server <b>118</b> and is received by the synchronization client <b>124</b> at the remote device <b>120</b> end. The tracker <b>710</b> on the autodestruct client <b>125</b> tracks the location and type of this data. The user in charge of the data subsequently changes the type of this data to non-synchronized <b>410</b>. Upon request from the remote access client <b>122</b>, the remote access server <b>116</b> communicates this data and its associated type to the remote access client <b>122</b>. The tracker <b>710</b> of the autodestruct client <b>123</b> records the location and type of this data such that this data can be destroyed upon command. In another option, the synchronization server <b>118</b> may communicate the change in the type of data to the tracker <b>710</b> of the autodestruct client <b>125</b> of the synchronization client <b>124</b> during each synchronization event. The tracker <b>710</b> of the autodestruct client <b>125</b> of the synchronization client <b>124</b> may communicate the change in the type of the data to the tracker <b>710</b> of the autodestruct client <b>123</b> of the remote access client <b>122</b>. The communication between the two trackers keeps both apprised of the location and type of each data unit.
0094In general, the remote device <b>120</b> is in synchronization with the server system <b>110</b> at the organization's head office when the device <b>120</b> is first compromised. The device <b>120</b> may be compromised if it is lost or stolen or if the employee in control of the device <b>120</b> loses authorized status. An example may be when an employee is terminated but retains possession of the remote device <b>120</b>. For encountering such situations, a mechanism provided by the embodiments of this invention enables the user in charge of the data at the organization to disable the device <b>120</b> remotely. For example, in the case of a terminated employee, the user in charge of the data at the organization may indicate to the remote device <b>120</b> that the employee's account is no longer valid and the employee should not be able to access the data.
0095A variety of approaches are taken by the embodiments of the invention depending on what the user in charge of the data suspects. The invention may merely sever the link between the remote device <b>120</b> and the server <b>110</b>. This approach cuts the remote device's <b>120</b> access to the data available on the server <b>110</b> while leaving the data already on the remote device <b>120</b> open to the unauthorized user. The invention may both sever the link and erase all synchronized data available on the remote device <b>120</b>. This option is used when the data does not lose its value with time and the data on the remote device must not fall in strangers' hands either. The invention may sever the link, delete the data, and delete the applications on the remote device <b>120</b>. In this scenario, the applications are also sensitive and proprietary and should not be compromised. In addition, as discussed above, the remote device <b>120</b> can self-initiate an erasure/encryption procedure.
0096<figref idref="DRAWINGS">FIG. 7B</figref> is a block diagram illustrating an encryption client system <b>750</b>. This block diagram may refer to the encryption client <b>160</b> included in the remote access client <b>122</b> or the encryption client <b>162</b> included in the synchronization client <b>124</b>. Both encryption client systems <b>160</b> and <b>162</b> have the same components that perform generally the same operations. Therefore, the components of the two encryption client systems <b>160</b> and <b>162</b> are being discussed together.
0097The encryption client system <b>750</b> includes an encryption engine <b>760</b>, encryption algorithms <b>770</b> and encryption keys <b>780</b>. The encryption engine <b>760</b>, in response to commands from the system <b>110</b> or when self-initiated, encrypts remote device data <b>121</b> or subsets thereof. The data to encrypt is specified in the set procedures file <b>170</b> and/or <b>175</b> in the server <b>110</b> or the set procedures file <b>180</b> and/or <b>185</b> in the remote device <b>120</b>. For example, the set procedures file <b>180</b> can specify encryption of all non-synchronized data <b>510</b> and all personally owned data <b>530</b>.
0098The encryption algorithms <b>770</b> are the algorithms used to encrypt the remote device data <b>121</b>. The algorithms <b>770</b> can include public key algorithms, symmetric key algorithms or other encryption algorithms. The keys used for the encryption algorithms <b>770</b> are stored in the encryption keys <b>780</b>. If the encryption keys <b>780</b> are the same as the decryption keys, then the keys <b>780</b> are erased after encryption by the erasure controller <b>610</b> and the corresponding keys are stored in the server <b>110</b> in encryption keys <b>680</b>. If the encrypted data cannot be decrypted using the encryption keys <b>780</b>, the keys <b>780</b> do not need to be erased after encryption.
0099<figref idref="DRAWINGS">FIG. 8A</figref> and <figref idref="DRAWINGS">FIG. 8B</figref> together depict a flowchart illustrating a process for automatically destroying data and applications on a remote device <b>120</b> and severing the connection of the remote device <b>120</b> to the server system <b>110</b>. The process illustrated is only an example of various processes that may be implemented using embodiments of the invention. This process is set forth from the viewpoint of the server <b>110</b>.
0100In the process of <figref idref="DRAWINGS">FIGS. 8A and 8B</figref> the server system <b>110</b> that is in communication with a remote device <b>120</b> receives (<b>810</b>) an indication that the remote device <b>120</b> is no longer authorized to access the server system. In various scenarios and examples, an authorized field user who has lost its remote device <b>120</b> may inform the user in charge of the data at the server <b>110</b> location that the remote device <b>120</b> has been compromised, the user in charge of the data at the server location may decide that the field user is no longer authorized to use the data or access the server, or some other event may precipitate that results in the remote device <b>120</b> losing its authorization to access the server system <b>110</b> or even the remote device data <b>121</b>. The indication that the remote device <b>120</b> is compromised may be entered into the server system <b>110</b> by the user in charge of the data, or may be communicated to the server system <b>110</b> by the remote device <b>120</b> itself. In the case that the indication is communicated to the server by the remote device <b>120</b> itself, the remote device <b>120</b> may be password protected or may include some type of theft prevention mechanism that causes the remote device <b>120</b> to communicate a message to the server system <b>110</b> in case the wrong password is entered or if the theft prevention mechanism is triggered otherwise. For example, the remote device <b>120</b> can communicate a message to the server system <b>110</b> if a user does not enter a password into the remote device <b>120</b> at a scheduled interval.
0101The server system <b>110</b> requests the remote device <b>120</b> to autodestruct in accordance with a set procedure. The set procedure is selected either by the user in charge of the data interactively based on a real time evaluation of the situation or by some preset mechanism that is triggered according to certain preset criteria. The set procedure determines the method and extent of self-destruction requested from the remote device <b>120</b>. For example, the server system <b>110</b> may check the sensitivity level of data <b>121</b> stored on the remote device <b>120</b> and check whether the remote device <b>120</b> is lost, stolen, in possession of a terminated employee, or simply loaned by one employee to another. Based on the combination of these preset conditions that are met, the server system may trigger some preset mechanism that deletes all or some of the data, limits access to certain data, severs the connection, or leaves the connection intact. The request is communicated from the server system <b>110</b> to the remote device <b>120</b> and comprises the following.
0102The server system <b>110</b> first checks (<b>815</b>) if a set procedure is selected that copies the remote data <b>121</b> to the server <b>110</b> or other location. If so, server <b>110</b> requests (<b>816</b>) the remote device <b>120</b> to transmit the remote data <b>121</b>. In an embodiment of the invention, the server system <b>110</b> may request (<b>816</b>) that the remote device <b>121</b> only transmit a subset of the remote device data <b>121</b>.
0103After requesting (<b>816</b>) the transmission or if no transmission of the remote data <b>121</b> is requested, the server system <b>110</b> checks (<b>817</b>) if the set procedure is selected that encrypts the remote data <b>121</b>. If the set procedure requires encryption, the encryption controller <b>660</b> requests (<b>818</b>) the remote device <b>120</b> to encrypt the remote data <b>121</b> or a subset thereof by transmitting a message to the encryption engine <b>760</b>. In an embodiment of the invention, the encryption controller <b>660</b> can also specify and/or transmit the encryption algorithms to use as well as the keys to use for encryption.
0104The server system <b>110</b> then checks (<b>819</b>) if a set procedure is selected that reformats the entire remote device <b>120</b>. In the embodiment depicted, reformatting the entire remote device <b>120</b> is the highest level of auto-destruction. If this set procedure is selected (<b>820</b>), the erasure controllers <b>610</b> of the autodestruct servers <b>117</b>, <b>119</b> communicate a request to the reformatter <b>730</b> to reformat the remote device <b>120</b>. The reformatter <b>730</b> erases all data including all applications but not necessarily the OS <b>291</b>. Because the reformatter <b>730</b> erases applications that maintain the communication between the remote device <b>120</b> and the server system <b>110</b>, erasing all applications automatically severs the connection between the remote device <b>120</b> and the server system <b>110</b>. The remote device <b>120</b> will be left with its operating system <b>291</b> and thus will remain a thinking and operating machine but will not contain any of the data units (points, files, or applications, etc.) installed on it by the user of the remote device <b>120</b> or the user in charge of the data at the server location and will not have any access to the server system <b>110</b> to resynchronize the data it lost. This option erases personally owned data <b>530</b>, as well, and may not be desirable or advisable in certain situations. On the other hand, this option is thorough and rapid.
0105If the reformatting set procedure is not selected (<b>819</b>), other procedures that erase the remote device data <b>121</b> might be used as specified in the set procedure. The server system <b>110</b> checks (<b>825</b>) to see if the selected set procedure indicates to erase the personally owned data <b>530</b> on the remote device <b>120</b>. This set procedure may be selected when a user that is not authorized to maintain personally owned data on the remote device nonetheless loads such data unto the device. This set procedure may also be selected when the user of the remote device that has been compromised needs to destroy his personally owned data but the other types of data are not sensitive enough to be destroyed. This set procedure may also be selected when a remote device is transferred from one user to another who may be using all of the data but not the personally owned data of the previous user. If this set procedure is selected, the server system requests (<b>830</b>) erasure of personally owned <b>530</b> data on the remote device <b>120</b>. The erasure controller <b>610</b> of the autodestruct server <b>117</b> of the remote access server <b>116</b> communicates a message to the data eraser <b>720</b> of the autodestruct client <b>123</b> of the remote access client <b>122</b> to erase only the personally owned data <b>530</b> of the remote device. The data eraser <b>720</b> proceeds to erase the data that the data tracker <b>710</b> of the autodestruct client <b>123</b> of the remote access client <b>122</b> has tracked as personally owned data <b>530</b>. As mentioned before, the data targeted for erasure is completely erased.
0106The server system <b>110</b> checks (<b>835</b>) if the selected set procedure indicates to erase the applications on the remote device <b>120</b>. If the set procedure selected indicates erasure of applications, the server system <b>110</b> communicates (<b>840</b>) to the remote device <b>120</b> to erase the applications. Applications are a category of data and may fall under the synchronized <b>520</b> or non-synchronized <b>510</b> type. Accordingly, erasure controllers <b>610</b> of the autodestruct servers <b>117</b>, <b>119</b> of both the remote access server <b>116</b> and the synchronization server <b>118</b> may communicate the request for erasure of applications of both types to the data erasers <b>720</b> of the autodestruct clients <b>123</b>, <b>125</b> of the remote access client <b>122</b> and synchronization clients <b>124</b>. The data erasers <b>720</b> subsequently proceed to completely erase the applications included in the remote device data <b>121</b>.
0107The server system <b>110</b> then checks (<b>845</b>) if the selected set procedure indicates to erase non-synchronized data <b>510</b>. If the set procedure selected indicates erasure of non-synchronized data <b>510</b>, the server system <b>110</b> communicates (<b>850</b>) to the remote device <b>120</b> to erase the non-synchronized data. The erasure controller <b>610</b> of the autodestruct server <b>117</b> of the remote access server <b>116</b> communicates to the data eraser <b>720</b> of the autodestruct client <b>123</b> of the remote access client <b>122</b> to erase the non-synchronized <b>510</b> remote device data. The data eraser <b>720</b> identifies the non-synchronized data <b>510</b> based on the information available from the data tracker <b>710</b> and proceeds to completely erase that data.
0108The server system <b>110</b> checks (<b>855</b>) if the selected set procedure indicates to erase synchronized data <b>520</b>. If the set procedure selected indicates erasure of synchronized data <b>520</b>, the server system <b>110</b> communicates (<b>860</b>) to the remote device <b>120</b> to erase the synchronized data. The erasure controller <b>610</b> of the autodestruct server <b>119</b> of the synchronization server <b>118</b> communicates to the data eraser <b>720</b> of the autodestruct client <b>125</b> of the synchronization client <b>124</b> to erase the synchronized <b>520</b> remote device data. The data eraser <b>720</b> identifies the synchronized data <b>520</b> based on the information available from the data tracker <b>710</b> and proceeds to completely erase that data.
0109The server system <b>110</b> then checks (<b>865</b>) if the selected set procedure indicates to sever the remote access connection with the remote device <b>120</b>. If the set procedure selected indicates to sever the connection, the server system communicates (<b>870</b>) to the remote device <b>120</b> to sever the remote access connection with the server system <b>110</b>. The remote device connection severing requestor <b>620</b> of the autodestruct server <b>117</b> of the remote access server <b>116</b> communicates a request to the remote device connection severing engine <b>740</b> of the autodestruct client <b>123</b> of the remote access client <b>122</b> to sever the remote access connection with the server system <b>110</b>. In response, the remote device connection severing engine <b>740</b> proceeds to sever the remote access connection between the server system <b>110</b> and the remote device <b>120</b>. In this scenario, the synchronization access has not been severed yet. As a result, only communication of non-synchronized data <b>510</b> ceases and synchronized data <b>520</b> may still continue to be communicated between the server system <b>110</b> and the remote device <b>120</b>. As mentioned earlier, if a data type is modified from non-synchronized to synchronized by the user in charge of the data, it may then be communicated via the synchronization server and client as the synchronization connection remains viable.
0110The server system <b>110</b> then checks (<b>875</b>) if the selected set procedure indicates to sever the synchronization connection with the remote device <b>120</b>. If the set procedure selected indicates to sever the connection, the server system <b>110</b> communicates (<b>880</b>) to the remote device <b>120</b> to sever the synchronization connection with the server system <b>110</b>. The remote device connection severing requestor <b>620</b> of the autodestruct server <b>119</b> of the synchronization server <b>118</b> communicates a request to the remote device connection severing engine <b>740</b> of the autodestruct client <b>125</b> of the synchronization client <b>124</b> to sever the synchronization connection with the server system <b>110</b>. The remote device connection severing engine <b>740</b> proceeds to sever the synchronization connection between the server system <b>110</b> and the remote device <b>120</b>. In this scenario, the non-synchronization access has not been severed (unless severed (<b>870</b>) earlier). As a result, only communication of synchronized data <b>520</b> ceases and non-synchronized data <b>510</b> may still continue to be communicated between the server system <b>110</b> and the remote device <b>120</b> if the remote access connection has not been earlier severed (<b>870</b>).
0111In short, the set procedures set forth in the process of <figref idref="DRAWINGS">FIGS. 8A and 8B</figref> permit total and complete severing of the connection between the server system <b>110</b> and the remote device <b>120</b>, complete encryption of the data <b>121</b>, a copying of the data <b>121</b>, a total and complete erasure of data <b>121</b> on the remote device or a selective severing of the connection and a selective erasure of data. The process of <figref idref="DRAWINGS">FIGS. 8A and 8B</figref> presents only some of the possible scenarios and scenarios of a different mix and match of connection severing and data erasure may also be accomplished by embodiments of this invention.
0112In an example security breach scenario, an unauthorized user in custody of the remote device <b>120</b> may attempt to turn off the communication capability so as to prevent the server system <b>110</b> from requesting destruction of the remote device data <b>121</b>. However, it would be difficult to do so before the user in charge of the data at the global server requests erasure of the data. In the case of remote devices <b>120</b> containing sensitive data, a timed autodestruct feature may be imbedded within the remote device data erasers <b>720</b> or reformatter <b>730</b> that would automatically erase the sensitive data, identified by type or category, at certain time intervals unless a password is entered into or communicated to the remote device <b>120</b>.
0113<figref idref="DRAWINGS">FIGS. 9A and 9B</figref> depict a flowcharts illustrating processes for automatically destroying data and applications on a remote device <b>120</b> and severing the connection of the remote device <b>120</b> to the server system <b>110</b>. The process illustrated is only an example of various processes that may be implemented using embodiments of the invention. This process is set forth from the viewpoint of the remote device <b>120</b>.
0114In the process of <figref idref="DRAWINGS">FIG. 9A</figref> the remote device <b>120</b> that is in communication with a server system <b>110</b> sends (<b>905</b>), in an embodiment of the invention, an indication that the remote device <b>120</b> is compromised. The remote device <b>120</b> may be password protected or include some type of theft prevention mechanism that causes the remote device <b>120</b> to communicate a message to the server system <b>110</b> in case the wrong password is entered or if the theft prevention mechanism is triggered otherwise.
0115The remote device <b>120</b> then receives (<b>910</b>) commands from the server system <b>110</b> to copy, erase, and/or encrypt the remote device data <b>121</b> in accordance with a set procedure, such as a procedure in the set procedure file <b>170</b> or <b>175</b>, as described in <figref idref="DRAWINGS">FIGS. 8A and 8B</figref>. The set procedure determines the method and extent of self-destruction requested from the remote device <b>120</b>. The set procedure is selected either by the user in charge of the data interactively based on a real time evaluation of the situation or by some preset mechanism that is triggered according to certain preset criteria. The remote device <b>120</b> then executes (<b>915</b>) the received commands and the method depicted in <figref idref="DRAWINGS">FIG. 9A</figref> ends.
0116In <figref idref="DRAWINGS">FIG. 9B</figref>, the remote device <b>120</b> autonomously self-initiates an autodestruct process. The remote device <b>120</b> first determines (<b>920</b>) if it has been compromised. This can be determined (<b>920</b>) if a password has not been entered at a specified interval or if an incorrect password has been entered. In an alternative embodiment, this determination (<b>920</b>) can be made based on not receiving a communication at a specified interval from the system <b>110</b>. If the device <b>120</b> has not been compromised, the device <b>120</b> can initiate this determination (<b>920</b>) at a later time. Otherwise, the remote device <b>120</b> executes a set procedure as specified in a set procedures file <b>180</b> and/or <b>185</b>. The set procedure can include encryption, transmission, and/or erasure of all or a subset of the remote data <b>121</b> as mentioned above. The set procedure can also include severing connections between the remote device <b>120</b> and the network <b>150</b>.
0117In short, the set procedures executed in the process of <figref idref="DRAWINGS">FIGS. 9A and 9B</figref> permit total and complete severing of the connection between the server system <b>110</b> and the remote device <b>120</b>, a total and complete erasure of data <b>121</b> on the remote device, duplication of the data <b>121</b>, encryption of the data <b>121</b>, and/or a selective erasure of data. The process of <figref idref="DRAWINGS">FIGS. 9A and 9B</figref> presents only some of the possible scenarios. Scenarios of a different mix and match of connection severing and data erasure may also be accomplished by embodiments of this invention.
0118It will be appreciated by one of ordinary skill in the art that erasure of data <b>121</b> under the processes of <figref idref="DRAWINGS">FIGS. 8A and 8B</figref> and <figref idref="DRAWINGS">FIGS. 9A and 9B</figref> may occur in different mixes and matches of data types and categories. Only certain categories of data <b>121</b> may be targeted for erasure. For example, only organizational directory data may be selected for erasure. Depending on whether this data category is assigned synchronized or non-synchronized type, the autodestruct servers of the remote access server <b>117</b> or the synchronization server <b>119</b> may request erasure from the remote device <b>120</b>. The data tracker <b>710</b> would have the location of storage, the type, and the category of each data and makes it available to the data eraser <b>720</b> for selective erasing.
0119The foregoing description of the embodiments of the invention is by way of example only, and other variations of the above-described embodiments and processes are provided by the present invention. For example, although the server system is illustrated as a single device, the server system may include several computers networked together. Components of this invention may be implemented using a programmed general purpose digital computer, using application specific integrated circuits, or using a network of interconnected conventional components and circuits. The embodiments described herein have been presented for purposes of illustration and are not intended to be exhaustive or limiting. Many variations are possible in light of the foregoing teachings. For example, the embodiments described above may use instructions to effect data erasure or severance of the connections. In other embodiments, data erasure may also be accomplished by a synchronization event by deleting the data on the server system and instructing synchronization to delete the corresponding data on the remote device as well. On the other hand, mechanisms in the server system or the remote device may prevent or delay synchronization if the data on the remote device is deleted until it is confirmed that such deletion has not been accidental. As another example, in the above embodiments, deletion of data is accomplished by complete deletion and writing over the storage area not just tagging or pointing at it. In other embodiments, deletion may be accomplished by tagging or pointing at the deleted data. The method, system, and computer program product described are limited only by the claims that follow.
Contents5
12 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US11030338B2 | Cited by | United States of America | Applicant |
| US10540520B2 | Cited by | United States of America | Applicant |
| US10162983B2 | Cited by | United States of America | Applicant |
| WO0045243A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| WO0045243A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| WO0212985A2 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| WO0212985A2 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| EP0813133A2 | Cites | European Patent Office (EPO) | Applicant |
| EP0899647A2 | Cites | European Patent Office (EPO) | Applicant |
| EP0917077A2 | Cites | European Patent Office (EPO) | Applicant |
| US2001037407A1 | Cites | United States of America | Search report |
| US2002002685A1 | Cites | United States of America | Applicant |
| US2002066034A1 | Cites | United States of America | Applicant |
| US2002073334A1 | Cites | United States of America | Search report |
| US2002077999A1 | Cites | United States of America | Applicant |
| US2002098840A1 | Cites | United States of America | Applicant |
| US2002128972A1 | Cites | United States of America | Applicant |
| US2002133465A1 | Cites | United States of America | Applicant |
| US2002162011A1 | Cites | United States of America | Search report |
| JP2002216099A | Cites | Japan | Applicant |
| JP2002216099A | Cites | Japan | Applicant |
| JP2003005905A | Cites | Japan | Applicant |
| JP2003005905A | Cites | Japan | Applicant |
| US2003023561A1 | Cites | United States of America | Applicant |
| US2003097596A1 | Cites | United States of America | Applicant |
| US2003149662A1 | Cites | United States of America | Applicant |
| US2003162555A1 | Cites | United States of America | Applicant |
| US2004025053A1 | Cites | United States of America | Applicant |
| US2004068721A1 | Cites | United States of America | Applicant |
| US2004098715A1 | Cites | United States of America | Applicant |
| US2005003804A1 | Cites | United States of America | Applicant |
| US2007093243A1 | Cites | United States of America | Applicant |
| US2007130255A1 | Cites | United States of America | Applicant |
| GB2346716A | Cites | United Kingdom | Applicant |
| US4714995A | Cites | United States of America | Applicant |
| US4837811A | Cites | United States of America | Applicant |
| US4882752A | Cites | United States of America | Applicant |
| US5113041A | Cites | United States of America | Applicant |
| US5128739A | Cites | United States of America | Applicant |
| US5150407A | Cites | United States of America | Applicant |
| US5220501A | Cites | United States of America | Applicant |
| US5237614A | Cites | United States of America | Applicant |
| US5265159A | Cites | United States of America | Applicant |
| US5432999A | Cites | United States of America | Applicant |
| US5572696A | Cites | United States of America | Applicant |
| US5613012A | Cites | United States of America | Applicant |
| US5631947A | Cites | United States of America | Applicant |
| US5647002A | Cites | United States of America | Applicant |
| US5649099A | Cites | United States of America | Search report |
| US5652884A | Cites | United States of America | Applicant |
| US5664207A | Cites | United States of America | Applicant |
| US5666530A | Cites | United States of America | Applicant |
| US5675362A | Cites | United States of America | Applicant |
| US5684984A | Cites | United States of America | Applicant |
| US5687322A | Cites | United States of America | Applicant |
| US5694546A | Cites | United States of America | Applicant |
| US5696825A | Cites | United States of America | Applicant |
| US5713019A | Cites | United States of America | Applicant |
| US5717925A | Cites | United States of America | Applicant |
| US5727202A | Cites | United States of America | Applicant |
| US5745884A | Cites | United States of America | Applicant |
| US5748084A | Cites | United States of America | Search report |
| US5771354A | Cites | United States of America | Applicant |
| US5787441A | Cites | United States of America | Applicant |
| US5790790A | Cites | United States of America | Applicant |
| US5832483A | Cites | United States of America | Applicant |
| US5857201A | Cites | United States of America | Applicant |
| US5857206A | Cites | United States of America | Applicant |
| US5862325A | Cites | United States of America | Applicant |
| US5862346A | Cites | United States of America | Applicant |
| US5870477A | Cites | United States of America | Applicant |
| US5870759A | Cites | United States of America | Applicant |
| US5896497A | Cites | United States of America | Search report |
| US5903881A | Cites | United States of America | Applicant |
| US5928329A | Cites | United States of America | Applicant |
| US5940843A | Cites | United States of America | Applicant |
| US5958007A | Cites | United States of America | Applicant |
| US5960176A | Cites | United States of America | Applicant |
| US5987609A | Cites | United States of America | Applicant |
| US5991410A | Cites | United States of America | Applicant |
| US5999947A | Cites | United States of America | Applicant |
| US6006274A | Cites | United States of America | Applicant |
| US6034621A | Cites | United States of America | Applicant |
| US6049671A | Cites | United States of America | Applicant |
| US6085191A | Cites | United States of America | Applicant |
| US6085192A | Cites | United States of America | Applicant |
| US6108787A | Cites | United States of America | Applicant |
| US6125388A | Cites | United States of America | Applicant |
| US6128739A | Cites | United States of America | Search report |
| US6151606A | Cites | United States of America | Applicant |
| US6160873A | Cites | United States of America | Applicant |
| US6167253A | Cites | United States of America | Applicant |
| US6236971B1 | Cites | United States of America | Search report |
| US6240091B1 | Cites | United States of America | Applicant |
| US6286102B1 | Cites | United States of America | Applicant |
| US6317793B1 | Cites | United States of America | Applicant |
| US6330568B1 | Cites | United States of America | Applicant |
| US6389542B1 | Cites | United States of America | Applicant |
| US6401112B1 | Cites | United States of America | Applicant |
| US6412071B1 | Cites | United States of America | Applicant |
28 members in 8 offices
Members28
| Document | Office | Kind | |
|---|---|---|---|
| CA2495083A1 | Canada | A1 | |
| WO2004015576A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003259893A1 | Australia | A1 | |
| US2004117310A1 | United States of America | A1 | |
| EP1535159A1 | European Patent Office (EPO) | A1 | |
| CN1685316A | China | A | |
| JP2005535969A | Japan | A | |
| IL166762D0 | Israel | D0 | |
| EP1535159A4 | European Patent Office (EPO) | A4 | |
| CN100380337C | China | C | |
| AU2003259893B2 | Australia | B2 | |
| US2011004941A1 | United States of America | A1 | |
| JP4612416B2 | Japan | B2 | |
| US8012219B2 | United States of America | B2 | |
| EP2375336A1 | European Patent Office (EPO) | A1 | |
| EP2375336B1 | European Patent Office (EPO) | B1 | |
| US8696765B2 | United States of America | B2 | |
| US2014181918A1 | United States of America | A1 | |
| US9083707B2 | United States of America | B2 | |
| US2015310222A1 | United States of America | A1 | |
| EP2955896A1 | European Patent Office (EPO) | A1 | |
| EP1535159B1 | European Patent Office (EPO) | B1 | |
| US9672371B2 | United States of America | B2 | |
| US2017228553A1 | United States of America | A1 | |
| EP2955896B1 | European Patent Office (EPO) | B1 | |
| US9965643B2This record | United States of America | B2 | |
| US2018253564A1 | United States of America | A1 | |
| US11017105B2 | United States of America | B2 |
56 transactions on the USPTO file
Allowed after 1 non-final rejection and 1 final rejection.
- Non-final rejections
- 1
- Final rejections
- 1
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Expire PatentEXP. | EXP. | |
| Maintenance Fee Reminder MailedREM. | REM. | |
| Payment of Maintenance Fee, 4th Year, Large EntityM1551 | M1551 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Email NotificationEML_NTR | EML_NTR | |
| Filing Receipt - CorrectedFLRCPT.C | FLRCPT.C | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| After Final Consideration Program Additional Consideration and/or updated searchAFAC | AFAC | |
| Interview Summary - Applicant Initiated - TelephonicEXAT | EXAT | |
| Paralegal or electronic terminal disclaimer approvedP574 | P574 | |
| Terminal Disclaimer FiledDIST | DIST | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| PILOT- Request for After Final Consideration ProgramRAFC | RAFC | |
| Response after Final ActionA.NE | A.NE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Email NotificationEML_NTR | EML_NTR | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Email NotificationEML_NTR | EML_NTR | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| Application Is Now CompleteCOMP | COMP | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Sent to Classification ContractorPGPC | PGPC | |
| FITF set to NO - revise initial settingFTFI | FTFI | |
| Cleared by L&R (LARS)L128 | L128 | |
| Referred to Level 2 (LARS) by OIPE CSRL198 | L198 | |
| Patent Term Adjustment - Ready for ExaminationPTA.RFE | PTA.RFE | |
| PTO/SB/69-Authorize EPO Access to Search ResultsSREXR141 | SREXR141 | |
| Applicants have given acceptable permission for participating foreignAPPERMS | APPERMS | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Entity Status Set To Undiscounted (Initial Default Setting or Status Change)BIG. | BIG. | |
| Initial Exam Team nnIEXX | IEXX |
10 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lapsed due to failure to pay maintenance feeLapsedFP | FP | |
| Lapse for failure to pay maintenance feesLapsedPATENT EXPIRED FOR FAILURE TO PAY MAINTENANCE FEES (ORIGINAL EVENT CODE: EXP.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYLAPS | LAPS | |
| Information on status: patent discontinuationPATENT EXPIRED DUE TO NONPAYMENT OF MAINTENANCE FEES UNDER 37 CFR 1.362STCH | STCH | |
| Fee payment procedureMAINTENANCE FEE REMINDER MAILED (ORIGINAL EVENT CODE: REM.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Maintenance fee paymentMAFP | MAFP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication
- 09965643
- Application
- 15499995
Titles
- English
- System and method for preventing access to data on a compromised remote device
Patent term adjustment
- Applicant delay
- −35 days
- Net adjustment
- 0 days
Classification
- CPC, 17
- G06F21/62
- G06F21/6218
- H04L63/083
- G06F2221/2143
- H04L63/14
- H04L63/1425
- H04L63/1441
- H04L63/1416
- H04L67/1095
- H04W12/06
- H04W12/12
- H04W12/128
- H04W12/126
- H04W12/122
- H04L63/10
- G06F21/604
- G06F21/6209
- IPC, 14
- G06F21 00
- G06F21 62
- H04L29 06
- H04W12 06
- H04W12 12
- H04L29 08
- G06F21 24
- G06F11 30
- G06F12 14
- G06F15 00
- G06F21 20
- H04K1 00
- H04L9 00
- H04L9 32
- USPC, 1
- 709229000